US8892885B2

System and method for delivering a challenge response in an authentication protocol

Summary by NHIP

Active Script Authentication

The system authenticates users by delivering an active script component through a parameter of an access-challenge message. This script configures a user device to modify a static authentication interface when the network protocol is RADIUS and the reply-message field carries the executable code.

Claim Score by NHIP

Read claim 1, the broadest

Abstract

A system and method for authenticating a user that includes receiving an access-request of a network protocol at a challenge-response server; determining if an access-challenge message is required; delivering an active script component through a parameter of an access-challenge message of the network protocol when an access-challenge is required; receiving a challenge-response of a user; validating the challenge-response; and selectively sending an access-accept response for a valid challenge-response and sending an access-denied response for an invalid challenge-response.

US8892885B2, drawing sheet 1
Sheet 1 of 4

Term

6 yearsleft in the term

Expires 8 October 2032, including 38 days of term adjustment.

  1. Priority and filed
  2. Granted
  3. Today
  4. Expires

14 claims: 2 independent, 12 dependent

  1. 1
    Broadest claimClaim Score 60, broad(NHIP)A method for authenticating a user comprising:receiving an access-request of a network protocol at a challenge-response server, wherein the network protocol is a client/server protocol running in the application layer and using a user datagram protocol as transport;determining if an access-challenge message is required;configuring an active script component to modify an existing static authentication interface of a user device;delivering the active script component through a parameter of an access-challenge message of the network protocol when an access-challenge is required;receiving a challenge-response of a user;validating the challenge-response;and selectively sending an access-accept response for a valid challenge-response and sending an access-denied response for an invalid challenge-response.
  2. 10
    A method for authenticating network access comprising:receiving an access-request of a network protocol at a challenge response server, wherein the network protocol is a client server protocol running in the application layer and using the User Datagram Protocol (UDP) as transport;processing the access-request to verify credentials;the challenge response server selectively replying with an access-accepted message for verified credentials, an access-denied message if credentials are denied, and an access-challenge message if the credentials require a challenge to verify the credentials;configuring an active script component to transform an authentication interface of a user device;wherein replying with an access-challenge message includes embedding the active script component in a parameter of the access-challenge;receiving a challenge-response of a user;validating the challenge-response;and selectively sending an access-accept response for a valid challenge-response and sending an access-denied response for an invalid challenge-response.